Senior Analyst, GRC (Bengaluru)

Senior Analyst, GRC (Bengaluru)

05 Oct
|
Pocket FM
|
Bengaluru

05 Oct

Pocket FM

Bengaluru

About Us

Pocket FM is a leading audio entertainment platform that brings engaging, serialized fiction to millions of listeners across genres like romance, thriller, fantasy, and more. With over 130 million users globally and strong traction in markets like the US and Europe, we’re revolutionizing storytelling through audio.

Our unique model combines free listening with micropayments for premium content, powering strong business growth. In FY25, we reached an ARR of INR 2,000 crore, with over 100,000 hours of content on the platform. We're also at the forefront of innovation, leveraging AI-generated content to scale efficiently.

Role Overview

As a Senior Analyst in GRC, you will be a key contributor in building and maturing Pocket FM's governance, risk, compliance, and privacy program. Reporting to the Head of InfoSec, you will work closely with Legal, Engineering, Product, and Business teams to ensure that regulatory obligations are met, internal controls are effective, and data is handled responsibly. This role carries a 70:30 split between GRC and Privacy, and is ideal for someone who thrives on translating complex regulatory and risk frameworks into practical, executable outcomes in a fast-paced product environment.

Key Responsibilities

GRC Framework Management

- Own and operate Pocket FM's GRC framework; maintaining control libraries, performing risk assessments, tracking remediation efforts, and ensuring alignment with ISO 27001, SOC 2 Type II, and NIST CSF.
- Support internal and external audits (SOC 2, ISO 27001, ISO 27701) by preparing evidence, coordinating with control owners across teams, and managing audit timelines.
- Maintain and continuously improve the risk register; identifying, scoring, and tracking risks across the organization in collaboration with Security, Legal, and Engineering and other in-scope functions.
- Define and track GRC metrics and KPIs; prepare dashboards and reports for leadership and relevant stakeholders.

Privacy Program Operations

- Support the design and ongoing management of Pocket FM's privacy program, with primary focus on GDPR and CCPA/CPRA.
- Conduct and manage Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) for new products, features, and data processing activities, collaborating with Product Privacy and Engineering to identify and mitigate privacy risks early.




- Own and maintain Records of Processing Activities (RoPA), data flow maps, and data inventories across the organization.
- Assist in consent management operations; covering marketing consent, in-app data collection, push notification consent, and cookie consent; ensuring alignment with GDPR, CCPA/CPRA, and DPDPA requirements.
- Monitor the evolving global privacy and data protection regulatory landscape (GDPR, CCPA/CPRA, DPDPA, and emerging frameworks) and translate regulatory changes into actionable internal guidance.
- Serve as a privacy point of contact in collaboration with the Product Privacy team for Product, Engineering, Marketing, and Business teams, providing practical guidance on data handling and privacy-by-design principles.

Third-Party Risk Assessment (TPRA)

- Own and execute the Third-Party Risk Assessment process end-to-end; coordinating with Privacy, Legal, and Security teams to evaluate vendors and partners across risk dimensions including data handling, security posture, and contractual obligations.
- Conduct vendor due diligence reviews, assess Data Processing Agreements (DPAs), and ensure Data Processor engagements comply with GDPR Article 28, CCPA service provider requirements, and DPDPA Data Processor obligations.
- Maintain the vendor risk register, track remediation commitments from third parties, and flag high-risk engagements for escalation to Security or Legal leadership.
- Develop and maintain TPRA questionnaires, scoring rubrics, and intake workflows to standardize and scale the assessment process across the organization.

AI / ML Privacy & Compliance

- Assess privacy and compliance risks associated with AI and ML systems used at Pocket FM; covering training data sourcing, user profiling, personalization engines, and automated decision-making.
- Evaluate AI/ML use cases against GDPR Article 22 (automated decision-making), CCPA profiling provisions, and emerging AI governance frameworks.




- Collaborate with Engineering and Data Science teams to embed privacy-by-design principles into AI/ML pipelines and data processing workflows.

Incident Support & Awareness

- Assist in privacy and security incident response activities, including breach assessment, regulatory notification analysis under GDPR (72-hour rule), CCPA, and DPDPA, and post-incident documentation.
- Develop and deliver GRC and privacy awareness training to foster a culture of data protection and compliance across the organization.

Skills & Qualifications

Must-Have

- 4+ years of experience in GRC, data privacy, or a related compliance/risk management function.
- Strong working knowledge of GDPR and CCPA/CPRA; including controller/processor obligations, data subject rights, breach notification, and consent requirements.
- Working knowledge of DPDPA (India) and its practical compliance implications.
- Hands-on experience with GRC frameworks and standards. ISO 27001, SOC 2, ISO 27701, and NIST CSF.
- Experience conducting PIAs/DPIAs, maintaining RoPA, and managing data inventories.
- Experience owning or contributing to Third-Party Risk Assessment processes, including DPA review and vendor due diligence.
- Familiarity with consent management concepts and tools (SourcePoint, OneTrust, or similar).
- Exposure to cloud environments (AWS and/or GCP) and a working understanding of how data flows through modern web and mobile application architectures.
- Excellent written and verbal communication skills. Ability to translate complex regulatory language into clear, actionable guidance for non-legal and technical stakeholders.
- Strong organizational skills with the ability to manage multiple workstreams and prioritize effectively.
- Comfortable operating below a Lead, executing within defined program structures while taking ownership of assigned workstreams.

Positive to Have:

- Privacy or GRC certifications: CIPP/E, CIPP/A, CIPM, CIPT, CDPSE, or ISO 27001 Lead Implementer/Auditor.
- Experience working with privacy and GRC tooling such as SourcePoint, OneTrust, BigID, TrustArc, or equivalent GRC platforms.
- Familiarity with AI/ML privacy considerations and emerging AI governance frameworks (EU AI Act, NIST AI RMF).
- Experience in a consumer tech, media, or high-scale platform company.
- Familiarity with content licensing, digital rights management (DRM), or creator/IP-related privacy considerations.

📌 Senior Analyst, GRC (Bengaluru)
🏢 Pocket FM
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior analyst, grc (bengaluru) / bengaluru